Threats to Certificate Services and Mitigation Options

When you deploy Certificate Services, you need to consider a number of new threats that come along with them, including the following:

  • Compromise of a CA's key pair

  • Preventing revocation checking

  • Attempts to modify the CA configuration

  • Attempts to modify a certificate template

  • Addition of nontrusted CAs to the trusted root CA store

  • Enrollment Agents issuing unauthorized certificates

  • Compromise of a CA by a single administrator

  • Unauthorized recovery of a user's private key from the CA database

We will start this chapter by discussing each threat in detail and providing you with methods to mitigate these threats.

Compromise of a CA's Key Pair

Each CA in a CA hierarchy has a digital certificate that represents ...

Get Windows Server® 2008 Security Resource Kit now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.